Heap-based buffer overflow in TensorFlow - CVE-2021-29535
Published: May 13, 2021 / Updated: May 4, 2026
TensorFlow
TensorFlow
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in QuantizedMul when processing invalid quantization threshold tensors. A remote attacker can pass empty threshold tensors to trigger the overflow and cause a denial of service.
The issue occurs if any of the min_x, max_x, min_y, or max_y input tensors is empty instead of a valid scalar.